Published, banded by organisation size

GDPR Consultancy Pricing: Fixed Fees, No Surprises

Indicative fixed-fee prices for the four things our data protection consultants deliver: a GDPR gap analysis, a GDPR audit against the ICO framework, a DPIA, and a full GDPR compliance project, each banded by the size of your organisation. This is the one corner of the market where buyers actively search on cost and nobody publishes a figure, so we set our prices out up front. Every project is delivered in-house, and your engagement is confirmed at scoping.

Indicative pricing

Four deliverables, priced up front

Where most projects start

GDPR Gap Analysis

Where you stand against the UK GDPR today, and the gaps that matter most

From £1,950

per project, indicative, ex VAT

  • Micro or sole trader from £1,950; SME from £3,500; mid-market from £6,500
  • Your processing mapped against the UK GDPR and the ICO's expectations
  • The gaps that carry the most risk, separated from the ones that can wait
  • A prioritised, costed remediation plan you can act on or hand back to us
  • Delivered in-house by CyPro's data protection consultants, the same team throughout
What this covers

GDPR Audit (ICO framework)

A deeper, evidence-based audit of your data protection against the ICO framework

From £2,950

per project, indicative, ex VAT

  • Micro or sole trader from £2,950; SME from £4,950; mid-market from £8,500
  • An independent audit against the ICO's accountability and audit framework
  • Evidence gathered across your policies, records of processing, systems and controls
  • Findings and a prioritised action plan the business can put to work
  • Delivered in-house by CyPro's data protection consultants
What this covers

DPIA (single assessment)

One data protection impact assessment for a specific project or processing activity

From £1,450

per assessment, indicative, ex VAT

  • Micro or sole trader from £1,450; SME from £2,450; mid-market from £3,950
  • One assessment of the risks a new system, product or processing activity carries
  • Risks weighed against the UK GDPR, with mitigations you can put in place
  • A completed DPIA you can show the ICO or a client on request
  • Delivered in-house by CyPro's data protection consultants
What this covers

Full GDPR Compliance Project

From gap analysis through remediation to a re-check, run as one fixed-scope project

From £6,500

per project, indicative, ex VAT

  • Micro or sole trader from £6,500; SME from £12,000; mid-market from £20,000
  • A gap analysis or audit, the remediation work, and a re-check, scoped as one
  • Policies, records of processing, DPIAs and the supporting documentation put right
  • Hands-on remediation support, not just a list of what to fix
  • Delivered in-house by CyPro's data protection consultants, one team start to finish
What this covers

Ad-hoc support

A consultant day rate for work that does not fit a fixed scope

Advice, review time and hands-on help, bought by the day

From £950

per consultant day, indicative, ex VAT

For questions, reviews and support that sit outside a defined project, you can bring in a data protection consultant by the day. Where the work has a clear shape, we would rather hold it to a fixed fee, which is what the prices above are for. How the process runs.

Where to start

Most organisations start with a gap analysis

It maps where you stand and sets up everything that follows

From £1,950

per project, indicative, ex VAT

A gap analysis is the natural first step: it shows where you stand against the UK GDPR and produces the costed plan that shapes the audit, any DPIA work and the remediation. Commission the full compliance project and the gap analysis or audit is folded into it. How the process runs.

What sets the fee, stated plainly

The figures above are guide fixed-fee "from" starting points rather than firm quotes, and are confirmed for your organisation at scoping. Two things set the fee: the size of your organisation, because a sole trader carries far less processing to assess than a mid-market business, and the complexity of your data, meaning how much personal data you hold, how many systems and third parties it moves through, and how sensitive it is. Fees exclude VAT. Every project is delivered in-house by CyPro's data protection consultants; you deal with one team from the scoping call to the final report.

For comparison

Three ways to buy GDPR help, side by side

Pricing in this market stays behind a call from start to finish: the specialist boutiques and the larger advisory firms alike withhold the figure until you have spoken to them. Yet this is the one corner of the market where buyers actively search on cost, so published prices let you plan and compare before you speak to anyone. The table shows the differences.

Quote-only GDPR boutique Large advisory firm GDPR project work by CyPro
Pricing Quoted only after a call, no figure published Quoted after scoping, day-rate led Indicative fixed-fee prices, published on this page
Engagement Project or ongoing retainer, quoted case by case Often an ongoing retainer Fixed-scope project, not a retainer, delivered in-house
Who performs it Their own consultants A large team, GDPR one of many practices CyPro's data protection consultants, in-house, the same team throughout
Scope certainty Unknown until you are quoted Unknown until you are quoted Fixed fee against agreed scope, banded by organisation size
What you leave with A report A report A prioritised, costed remediation plan the business can act on

Asked about the fees

Pricing, explained further

Why publish fees when the rest of the market keeps them back?

Because a scoped piece of GDPR work carries a knowable cost, and holding the figure back tends to suit the seller more than the buyer. This is the one corner of the data protection market where organisations actively search on price, yet no competitor puts a figure in writing. Listing indicative prices is our answer to that, in keeping with the open pricing CyPro applies right across its specialist services. It lets you plan and compare before you speak to anyone, and your engagement is still confirmed at scoping.

Are these fixed fees?

Each figure is an indicative fixed-fee starting point rather than a firm quote. What sets the final figure is the size of your organisation and the complexity of your data: how much personal data you hold, how many systems and third parties it moves through, and how sensitive it is. Where the scope is clear, we hold the work to a fixed fee rather than an open day rate, which is the whole point of publishing them.

Who actually carries out the work?

CyPro's own data protection consultants, in-house, from the scoping call to the final report. The work is not subcontracted to a delivery partner, so you deal with one team throughout and the people who scope the project are the people who run it. The same consultants deliver the gap analyses, audits, DPIAs and full compliance projects.

Which one do we need?

A gap analysis shows where you stand against the UK GDPR and produces a costed plan. A GDPR audit is a deeper, evidence-based review against the ICO framework. A DPIA assesses one specific project or processing activity. A full compliance project runs from gap analysis through remediation to a re-check as a single piece of work. Most organisations start with a gap analysis, and the scoping call confirms what you actually need.

See how a project runs

Does the fee cover fixing the gaps you identify?

A gap analysis or audit gives you an independent view and a prioritised, costed remediation plan; acting on it can sit with your team, or you can bring us in to do the remediation. The full compliance project includes the remediation work and a re-check within one fixed scope. The consultant day rate covers ad-hoc support that does not fit a defined project. None of the figures above conceals a standing retainer.

Rocket above the GDPR Consultancy call to action

Prices published, scope confirmed on a call

Find the service that fits your organisation

One scoping call, taken by a data protection consultant, confirms which piece of work you need, the organisation-size bracket you sit in, and the fixed fee to put your GDPR compliance right.